DOJ indicts 17 Iranians over IP cyber theft claims
DOJ indicts 17 Iranian nationals over alleged 2013–2017 cyber espionage tied to Mabna Institute and 3.4 billion dollars in stolen data.
Atlas Newsdesk ·

The United States Department of Justice has indicted 17 Iranian nationals over an alleged, multi-year cyber espionage campaign aimed at academic, private-sector, and government organisations.
Officials said the case centres on an Iran-based entity identified as the Mabna Institute, which is accused of coordinating intrusions from 2013 to 2017 to obtain intellectual property and sensitive research data.
Targets and alleged method
According to the indictment, the operation relied on compromised login credentials to gain unauthorised access to university systems and other networks.
Prosecutors allege the campaign reached deeply into the US higher-education sector, with 144 American universities listed as victims alongside 42 private sector firms.
Scope of account targeting
Officials said the alleged actors systematically pursued access to academic identities on a global scale, targeting 100,000 academic accounts worldwide.
The indictment claims that 8,000 professor email accounts were successfully breached, enabling further access to research and other sensitive information.
Scale of alleged theft and affected institutions
The Department of Justice said the activity resulted in the theft of about 31 terabytes of data, which it values at an estimated 3.4 billion dollars.
In addition to universities and companies, the indictment alleges that multiple federal and state government agencies were also affected.
Alleged state-linked direction
Officials asserted that the conduct described in the charging documents was carried out on behalf of the Islamic Revolutionary Guard Corps.
Prosecutors said the purpose was to obtain non-Iranian scientific resources, framing the intrusions as an effort to capture research and intellectual property at scale.
Enforcement steps and what remains unknown
The Department of Justice said the new case follows a previous indictment filed in 2018 related to the same overall matter.
As part of the current enforcement effort, officials announced a 10 million dollar reward for information leading to the apprehension of five primary suspects.
While the indictment lays out the alleged timeframe, targets, and methods, the Department of Justice statement does not specify in this summary which data sets were most critical, how the stolen material was ultimately used, or whether any of the defendants are currently in US custody.
Why the case matters for institutions handling research
Officials said the case underscores how cyber operations have become a prominent tool in state-sponsored activity, particularly when the objective involves gaining access to research, intellectual property, and other high-value information.
For universities, companies, and government bodies, the allegations highlight the operational risks tied to credential compromise, including the possibility that a single breached account can open paths to wider repositories of sensitive data.